DuckDuckGo logo
DuckDuckGo

Independent internet privacy company. Download our browser with privacy built-in, unlike Chrome, on mobile & desktop.

Senior Web Security Engineer, Browser Platform

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 51-200Since 2008H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

172 days ago

Salary

$178.5K / year

Seniority

Senior

Bachelor Degree7 yrs expEnglishJavaScriptKotlinPerlSwiftGo

Job Description

Senior Web Security Engineer, Browser Platform

DuckDuckGo

• Conduct browser security audits (special pages, DuckAI integrations, password manager, etc.) • Execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code) • Manage application security scanning infrastructure setup (aka SAST/DAST integrations in GitHub) • Deliver on Internal red-team operations (simulated attack scenarios) • Support security triage

Job Requirements

  • 7+ years of experience in web or application security (performing security assessments, vulnerability research, penetration testing, or secure code review)
  • Advanced programming or scripting experience with JavaScript
  • Experience with at least one WebView technology (WebKit, WebView2, Chromium WebView, etc.)
  • Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws, etc.)
  • Familiarity with security testing tools and frameworks
  • Experience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code faster
  • Experience shaping how an organisation thinks about security - driving best practices, improving processes, and raising the bar across teams

Benefits

  • paid parental leave
  • office setup
  • co-working allowances

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 5,001-10,000H1B No Sponsor

• Diseñar e implementar prácticas de Seguridad en la Nube y DevSecOps • Asegurar la seguridad de los datos en entornos de nube • Desarrollar flujos de trabajo automatizados de detección y respuesta

Spain
Mozilla logo

Staff Security Engineer, Product Security

Mozilla

Feel good about your work again.

Security Engineer172 days ago
OtherRemoteTeam 501-1,000Since 1998H1B Sponsor

• Safeguard millions of users by embedding security into Firefox, Mozilla VPN, and other mission-critical products. • Ensure software products are secure by embedding security into the full Software Development Life Cycle (SDLC). • Anticipate, prioritize and mitigate risks through proactive threat modeling, security assessments, security testing, and automation. • Perform security code reviews • Lead penetration testing on web, mobile, and embedded applications, then guide remediation efforts. • Develop and maintain automated security tests within CI/CD pipelines to catch vulnerabilities early. • Partner with engineers to integrate security throughout the software development lifecycle—not as an afterthought, but as a core design principle. Provide security guidance, develop secure solutions, and facilitate secure releases. • Help define and enforce security policies and provide security guidance to development teams. • Help shape Mozilla's security culture through collaboration, guidance, and education.

United States
$138K - $217K / year
Job Closed

• Secure client IT assets against cyber threats, including malware, ransomware, and unauthorized access attempts • Monitor and analyze security tools and logs to detect suspicious activity and potential incidents • Stay current on threat intelligence and emerging attack techniques • Investigate, triage, and respond to security incidents, including containment and remediation activities • Collaborate with client end users to assess security needs and recommend appropriate solutions • Configure, maintain, and support security technologies such as EDR, firewalls, IDS/IPS, DNS security, MFA, application security, and email security • Implement and maintain strong Microsoft 365 security practices, including conditional access, MFA, and business email compromise prevention and remediation • Participate in vulnerability management efforts using commercial vulnerability scanning tools • Assist with client, server, and laptop configurations, installations, and troubleshooting as needed • Engage in client discussions around security vulnerabilities, mitigation strategies, and best practices • Apply data encryption best practices to protect data at rest • Analyze security data and generate reports for internal and client stakeholders • Provide occasional after-hours and weekend support during active incident response efforts.

United States
$85K - $100K / year
Job Closed
FICO logo

Principal Data and AI Security Architect

FICO

FICO is an analytics company helping businesses make better decisions that drive higher levels of growth and success.

Security Engineer172 days ago
OtherRemoteTeam 1,001-5,000Since 1956H1B No Sponsor

• Secure the design of AI and ML capabilities within FICO Platform, services and corporate tools. • Provide full-stack security architecture design from cloud infrastructure to application features for FICO and internal customers. • Oversee security aspects of Analytical Model Life Cycle, and influence stakeholders for adopting best security standards and implementations. • Define comprehensive data security strategy and guide implementation of enterprise-wide data protection programs including DLP, data classification, security logging, and data protection controls across products and enterprise systems. • Proof the security implementations within infrastructure & application deployment manifests and the MLSecOps pipeline. • Define required controls and capabilities for the protection of FICO AI and data services and environments and collaborate with architects, developers and product managers, to implement security controls at scale. • Design, Implement and manage scalable security controls and automation in a DevOps environment within public clouds (AWS, Azure, GCP, Oracle) across IaaS, PaaS, SaaS, and container platforms. • Integrate security in depth throughout FICO software delivery processes and pipelines.

United States
$161K - $253K / year
Job Closed